<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Gumblar .cn Exploit &#8211; 12 Facts About This Injected Script</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Thu, 18 Mar 2010 09:08:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Securing FTP Access on a cPanel Server :: The cPanel Admin</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6743</link>
		<dc:creator>Securing FTP Access on a cPanel Server :: The cPanel Admin</dc:creator>
		<pubDate>Thu, 11 Feb 2010 17:53:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6743</guid>
		<description>[...] with viruses like Gumblar stealing FTP passwords and farming them out to hackers so they can upload malicious code into user files. What you end up with is a flood of complaints from users about errors on their [...]</description>
		<content:encoded><![CDATA[<p>[...] with viruses like Gumblar stealing FTP passwords and farming them out to hackers so they can upload malicious code into user files. What you end up with is a flood of complaints from users about errors on their [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Top 10 Malware Sites &#124; Decentralization Station &#124; Power of the cloud</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6514</link>
		<dc:creator>Top 10 Malware Sites &#124; Decentralization Station &#124; Power of the cloud</dc:creator>
		<pubDate>Wed, 06 Jan 2010 12:35:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6514</guid>
		<description>[...] malware researchers reported widespread compromises pointing to the domains gumblar.cn and martuz.cn, both of which made it on [...]</description>
		<content:encoded><![CDATA[<p>[...] malware researchers reported widespread compromises pointing to the domains gumblar.cn and martuz.cn, both of which made it on [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Malicious Javascript Code infected my blogs - Ryan Isra, Cyberworld, Technology</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6449</link>
		<dc:creator>Malicious Javascript Code infected my blogs - Ryan Isra, Cyberworld, Technology</dc:creator>
		<pubDate>Wed, 30 Dec 2009 19:44:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6449</guid>
		<description>[...] its name is Gumblar. You can find further information about Gumblar on Unmask Parasites Blog, Wikipedia, or ISS.net. I got alot of useful information. However, I might be infected by its [...]</description>
		<content:encoded><![CDATA[<p>[...] its name is Gumblar. You can find further information about Gumblar on Unmask Parasites Blog, Wikipedia, or ISS.net. I got alot of useful information. However, I might be infected by its [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Markusk</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6268</link>
		<dc:creator>Markusk</dc:creator>
		<pubDate>Wed, 16 Dec 2009 22:14:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6268</guid>
		<description>If you know the date of the infection, you can easily check all files that were edited on that day. 

btw, I noticed, it replaced a file called home.inc, so it probably also targets all files containing &quot;home&quot; in the name, additionally to &quot;index&quot;, &quot;default&quot;, etc and ALL .js files.</description>
		<content:encoded><![CDATA[<p>If you know the date of the infection, you can easily check all files that were edited on that day. </p>
<p>btw, I noticed, it replaced a file called home.inc, so it probably also targets all files containing &#8220;home&#8221; in the name, additionally to &#8220;index&#8221;, &#8220;default&#8221;, etc and ALL .js files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ugg outlet</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6214</link>
		<dc:creator>ugg outlet</dc:creator>
		<pubDate>Sun, 13 Dec 2009 12:49:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6214</guid>
		<description>Make sure to check the folders “error_docs” and “httpsdocs” on your webserver!!!

The malicious code can also be found in these locations – therefore the infection will not be cured if you just upload a clean backup version of your website from a clean system unless you sanitize those locations too.</description>
		<content:encoded><![CDATA[<p>Make sure to check the folders “error_docs” and “httpsdocs” on your webserver!!!</p>
<p>The malicious code can also be found in these locations – therefore the infection will not be cured if you just upload a clean backup version of your website from a clean system unless you sanitize those locations too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pratclif</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-5770</link>
		<dc:creator>pratclif</dc:creator>
		<pubDate>Wed, 18 Nov 2009 17:09:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-5770</guid>
		<description>I have several sites; you rightly pont to the password security. I have  like this ......
 

inserted before &lt;body tag in all my html pages. I replace them with clean files from my hard disk; but next day the files are again corrupt with new &lt;script with a new url</description>
		<content:encoded><![CDATA[<p>I have several sites; you rightly pont to the password security. I have  like this &#8230;&#8230;</p>
<p>inserted before &lt;body tag in all my html pages. I replace them with clean files from my hard disk; but next day the files are again corrupt with new &lt;script with a new url</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ReBirth &#171; Zero Wind &#8211; Jamie Wong</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-5405</link>
		<dc:creator>ReBirth &#171; Zero Wind &#8211; Jamie Wong</dc:creator>
		<pubDate>Thu, 05 Nov 2009 05:47:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-5405</guid>
		<description>[...] The virus that owned the old site (along with every other index.* on my webspace) was a variant of the Gumblar.cn virus http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/ [...]</description>
		<content:encoded><![CDATA[<p>[...] The virus that owned the old site (along with every other index.* on my webspace) was a variant of the Gumblar.cn virus <a href="http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/" rel="nofollow">http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ugg boots</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-5313</link>
		<dc:creator>ugg boots</dc:creator>
		<pubDate>Mon, 02 Nov 2009 09:42:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-5313</guid>
		<description>Our site was infected 14 days ago. So we cleaned the server, installed all new with all security updates, newest php and sql version, even new joomla!.
Now, our webserver has been infected the second time… There are a lot of tutorials how to desinfect the webserver (or just clean up by deleting everything), but what is with the Computer? How can we clean possible infectet computers too? We use a SonicW… Firewall with content filter, and TrendM…</description>
		<content:encoded><![CDATA[<p>Our site was infected 14 days ago. So we cleaned the server, installed all new with all security updates, newest php and sql version, even new joomla!.<br />
Now, our webserver has been infected the second time… There are a lot of tutorials how to desinfect the webserver (or just clean up by deleting everything), but what is with the Computer? How can we clean possible infectet computers too? We use a SonicW… Firewall with content filter, and TrendM…</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: EL_Barto</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-5133</link>
		<dc:creator>EL_Barto</dc:creator>
		<pubDate>Thu, 29 Oct 2009 18:38:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-5133</guid>
		<description>Make sure to check the folders &quot;error_docs&quot; and &quot;httpsdocs&quot; on your webserver!!!

The malicious code can also be found in these locations - therefore the infection will not be cured if you just upload a clean backup version of your website from a clean system unless you sanitize those locations too.</description>
		<content:encoded><![CDATA[<p>Make sure to check the folders &#8220;error_docs&#8221; and &#8220;httpsdocs&#8221; on your webserver!!!</p>
<p>The malicious code can also be found in these locations &#8211; therefore the infection will not be cured if you just upload a clean backup version of your website from a clean system unless you sanitize those locations too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ken</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-4868</link>
		<dc:creator>Ken</dc:creator>
		<pubDate>Sat, 24 Oct 2009 17:51:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-4868</guid>
		<description>As a FYI, a friend sites got hit with this with continuous re-infections. I wrote a windows service that monitored his server and while not stopping the infection it does immediately fix the infections. I have a few more days of testing but will post it at

http://reddwarfdogs.com/websitehack/ around oct 27th..</description>
		<content:encoded><![CDATA[<p>As a FYI, a friend sites got hit with this with continuous re-infections. I wrote a windows service that monitored his server and while not stopping the infection it does immediately fix the infections. I have a few more days of testing but will post it at</p>
<p><a href="http://reddwarfdogs.com/websitehack/" rel="nofollow">http://reddwarfdogs.com/websitehack/</a> around oct 27th..</p>
]]></content:encoded>
	</item>
</channel>
</rss>
